Python 'Lib/webbrowser.py' Remote Command Execution Vulnerability
BID:102207
Info
Python 'Lib/webbrowser.py' Remote Command Execution Vulnerability
| Bugtraq ID: | 102207 |
| Class: | Design Error |
| CVE: |
CVE-2017-17522 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2017 12:00AM |
| Updated: | Dec 19 2017 09:01PM |
| Credit: | The vendor has reported this issue. |
| Vulnerable: |
Python Software Foundation Python 3.6.3 Python Software Foundation Python 3.5.2 Python Software Foundation Python 3.5 Python Software Foundation Python 3.4.5 Python Software Foundation Python 3.4.3 Python Software Foundation Python 3.4.2 Python Software Foundation Python 3.4.1 Python Software Foundation Python 3.3.3 Python Software Foundation Python 3.3 Python Software Foundation Python 3.2.3 Python Software Foundation Python 3.2.2 Python Software Foundation Python 3.1.1 Python Software Foundation Python 3.0.1 Python Software Foundation Python 2.7.12 Python Software Foundation Python 2.7.10 Python Software Foundation Python 2.7.9 Python Software Foundation Python 2.7.8 Python Software Foundation Python 2.7.7 Python Software Foundation Python 2.7.6 Python Software Foundation Python 2.7.3 Python Software Foundation Python 2.7.2 Python Software Foundation Python 2.7 Python Software Foundation Python 2.6.5 Python Software Foundation Python 2.6.2 Python Software Foundation Python 2.5.6 Python Software Foundation Python 2.5.5 Python Software Foundation Python 2.5.3 Python Software Foundation Python 3.7.0 Python Software Foundation Python 3.6 Python Software Foundation Python 3.5 Python Software Foundation Python 3.4.0 Python Software Foundation Python 3.4 Python Software Foundation Python 3.3.4 Python Software Foundation Python 3.3.2 Python Software Foundation Python 3.3.1 Python Software Foundation Python 3.3 Python Software Foundation Python 3.2.6 Python Software Foundation Python 3.2.5 Python Software Foundation Python 3.2.4 Python Software Foundation Python 3.2.1 Python Software Foundation Python 3.2.0 Python Software Foundation Python 3.2 Python Software Foundation Python 3.1.5 Python Software Foundation Python 3.1.4 Python Software Foundation Python 3.1.3 Python Software Foundation Python 3.1.2 Python Software Foundation Python 3.1 Python Software Foundation Python 2.7.5 Python Software Foundation Python 2.7.4 Python Software Foundation Python 2.7.1 Python Software Foundation Python 2.7 Python Software Foundation Python 2.6.8 Python Software Foundation Python 2.6.7 Python Software Foundation Python 2.6.6 Python Software Foundation Python 2.6.3 Python Software Foundation Python 2.6 |
| Not Vulnerable: | |
Discussion
Python 'Lib/webbrowser.py' Remote Command Execution Vulnerability
Python is prone to a remote command-execution vulnerability.
Attackers can exploit this issue to execute arbitrary command within the context of user running the affected application. Failed exploit attempts may result in a denial-of-service condition.
Python is prone to a remote command-execution vulnerability.
Attackers can exploit this issue to execute arbitrary command within the context of user running the affected application. Failed exploit attempts may result in a denial-of-service condition.
Solution / Fix
Python 'Lib/webbrowser.py' Remote Command Execution Vulnerability
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
References
Python 'Lib/webbrowser.py' Remote Command Execution Vulnerability
References:
References:
- [Security] CVE-2017-17522: webbrowser.py in Python does not validate strings (Python)
- python home page (python)
- bugzilla advisory (redhat)
- CVE-2017-17522 (debian)
- redhatadvisory (redhat)